FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. Gleam

Gleam

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Gleam do?

Gleam is a marketing app suite (Competitions, Rewards, Galleries, Capture) embedded as a JavaScript widget on a publisher site. It collects participant entries, connects to social networks (Facebook, Twitter, Instagram, TikTok) to verify actions, and stores the data on Gleam.io servers in Australia. As a third party widget loading social plugins, it requires prior consent under the GDPR and the ePrivacy Directive.

What is Gleam?

Gleam.io is an Australian SaaS that powers giveaways, competitions, sweepstakes, rewards programmes and user generated galleries. Its widgets are embedded as a JavaScript snippet on the publisher site and orchestrate the entry workflow, verifying actions via integrations with Facebook, Twitter, Instagram, TikTok, YouTube, Discord and dozens of other platforms. Gleam is widely used by ecommerce, gaming and media publishers in Europe.

Cookies and identifiers

The Gleam widget sets first party cookies (gleam_session, gleam_anon_id) to deduplicate entries and remember the participant''s state inside a campaign. When a user connects a social account, Gleam stores the OAuth token and a hashed user ID on its servers. Embedded social plugins can in turn drop their own third party cookies.

GDPR and ePrivacy implications

Loading the gleam.js widget triggers cookie storage and the loading of third party social plugins, which both fall under Article 5(3) ePrivacy and require prior consent. The processing of participant data, social IDs and email addresses for promotional purposes additionally requires a clear legal basis under the GDPR, typically consent or contract performance for the giveaway terms.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and social plugin handling

Block the Gleam widget through your CMP until the visitor accepts the marketing category. Use the click to consent pattern for social plugins inside the widget so that no Facebook, Twitter or Instagram cookie is dropped before the user explicitly chooses to connect. Document the giveaway terms and the data retention separately for participants who win and those who do not.

Data transfers

Gleam.io Pty Ltd is established in Melbourne, Australia, and runs infrastructure in Australia, the United States and Cloudflare edges worldwide. The EU Commission has not adopted an adequacy decision for Australia, so the transfer must rely on Standard Contractual Clauses with supplementary measures, plus an EU U.S. Data Privacy Framework certification for any US subprocessor.

Implementing Gleam compliantly

Gate the widget on a CMP signal, sign the Gleam Data Processing Addendum, document Gleam.io Pty Ltd in your records of processing as a processor in Australia, define a retention policy for entries and OAuth tokens, and provide entrants with a clear privacy notice for the giveaway.

GDPR consent category

Marketing

Websites using Gleam must obtain user consent under GDPR regulations.

Legal basisPrior consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy: the widget loads third party JavaScript, sets cookies and integrates social plugins (Facebook, Twitter, Instagram) that profile the user.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, Standard Contractual Clauses (Australia transfer)

DPIA considerations

A DPIA should be considered when Gleam campaigns process large volumes of personal data, when special categories are collected (preferences, location), or when integrations send data to social platforms with their own targeting beyond verification.

Sample consent text

We use Gleam.io to run giveaways and competitions on this site. With your consent, Gleam will set cookies on your device, load social plugins (Facebook, Twitter, Instagram) and transfer your entry data to Gleam.io Pty Ltd in Australia. You can refuse or withdraw your consent at any time from the cookie settings.

Technical details

Tracking methodJavaScript widget (gleam.js loaded from gleam.io and assets.gleam.io) embedded on the publisher site that hosts giveaway, competition, reward and gallery campaigns, sets first party cookies for entry deduplication and forwards entries plus connected social accounts to Gleam servers.
Server locationAustralia (primary) and United States (CDN), with regional CloudFlare edges.
Data transferred outside the EUEntries, IP addresses and connected social account data are transferred to Gleam.io Pty Ltd in Australia (the EU Commission has not adopted an adequacy decision for Australia) and to its US based subprocessors, requiring Standard Contractual Clauses.

Third-party domains contacted

gleam.ioassets.gleam.iowidget.gleam.iocdn.gleam.io

Cookies placed

NameTypeDurationPurpose
gleam_sessionfirst_partysessionStores the participant's session state inside a Gleam campaign and enables anti fraud checks during the entry workflow.
gleam_anon_idfirst_party6 monthsAnonymous identifier used by Gleam to deduplicate entries and recognise returning participants across sessions.
__cf_bmthird_party30 minutesCloudflare bot management cookie set on gleam.io to mitigate automated traffic and protect the giveaway from cheating.

Gleam places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Gleam set?

The Gleam widget sets first party cookies (gleam_session, gleam_anon_id) to deduplicate entries and remember the participant's state. Connecting a social account causes Gleam and the social plugin to drop additional third party cookies.

Does Gleam require consent?

Yes. The widget loads third party JavaScript and writes cookies that are not strictly necessary, so prior consent is required under Article 5(3) of the ePrivacy Directive. The processing of participant data also requires a clear GDPR legal basis.

What is the legal basis?

For voluntary actions like email submissions, consent is the appropriate basis. For mandatory entry conditions (filling in a participant form), contract performance for the giveaway terms can apply, but cookie storage still needs consent.

Are data transferred outside the EU?

Yes. Gleam.io Pty Ltd is based in Australia and uses US sub processors. Australia is not covered by an EU adequacy decision, so the transfer relies on Standard Contractual Clauses with supplementary measures.

Do I need a DPIA for Gleam?

A DPIA is recommended when Gleam is used to collect large volumes of personal data, when sensitive categories are processed, or when the data is shared with third party platforms beyond mere verification.

How do I deploy Gleam compliantly?

Block the widget through your CMP until consent, use click to consent for social plugins, sign the Gleam DPA, define a retention policy for entries and OAuth tokens, and publish a clear giveaway privacy notice.

Are there alternatives to Gleam?

EU hosted alternatives include Drimify, Qualifio (Belgium) or Easypromos (Spain), all of which offer giveaway and contest mechanics with EU data residency.

How do I update my cookie policy?

Add a section that names Gleam.io, lists the cookies (gleam_session, gleam_anon_id) with purpose and duration, mentions the embedded social plugins (Facebook, Twitter, Instagram, etc.) and discloses the transfer to Gleam.io Pty Ltd in Australia.